Ravens PHP Scripts

Sun Java System Active Server Pages Multiple Vulnerabilities
Date: Friday, September 04, 2009 @ 00:42:31 UTC
Topic: Security


SECUNIA ADVISORY ID: SA36586

VERIFY ADVISORY: http://secunia.com/advisories/36586/

DESCRIPTION: Some vulnerabilities have been reported in Sun Java System Active Server Pages, one having an unspecified impact, while others can be exploited by malicious users to compromise a vulnerable system and by malicious people to cause a DoS (Denial of Service). The vulnerabilities are reported in version 4.0.3. Other versions may also be affected.



1) Two unspecified errors can be exploited to cause stack-based buffer overflows. Successful exploitation may allow execution of arbitrary code, but may require valid user credentials.

2) An unspecified error can be exploited in the pre-authentication phase.

3) An unspecified error can be exploited to cause a "stack overflow".

SOLUTION: Restrict access to trusted users only.

PROVIDED AND/OR DISCOVERED BY: Reportedly a module for VulnDisco Pack.

ORIGINAL ADVISORY: http://intevydis.com/vd-list.shtml






This article comes from Ravens PHP Scripts
https://www.ravenphpscripts.com

The URL for this story is:
https://www.ravenphpscripts.com/modules.php?name=News&file=article&sid=3671